Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Feature Request: Sanitize Auto-Tracked Resource URLs Before Reporting

Open
#1,327 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 3 days

@teplymax is already working on this.

Since Jul 7, 2026.

  • #1328 by @teplymax — open

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
52/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Quiet
Tech stack
react-native, typescript
Domain
mobile

Research direction

Start by reading the automatic XHR resource tracking flow around resourceEventMapper and native startResource, then review the proposed branch and patch linked in the issue. Check how registerResourceEventMapper and unregisterResourceEventMapper affect already-enabled tracking. Done means rewritten URLs reach reported resources, null drops them before native tracking, and existing tracing and internal filters continue to work.

Written by the indexing model from the issue text.

Description

enhancement
Feature description

Feature Description

Use case

We want to sanitize URLs of resources reported to Datadog from React Native apps to prevent
PII leaks through query parameters or other URL components.

For example, an auto-tracked resource URL like:

https://testurl.com?phone=12345

should be reported as:

https://testurl.com?phone=PHONE_PLACEHOLDER

This would let mobile apps apply the same resource URL sanitization strategy that our
frontend already supports, giving us consistent privacy controls across web and mobile
instrumentation.

How the SDK currently delivers this

The React Native SDK exposes resourceEventMapper, but the automatic XHR resource tracking
flow does not give it enough control before native RUM resource tracking starts.

In the current flow, URL-based filtering or sanitization can happen too late. The native
resource may already be started before the mapper has enough resource context to decide
whether the event should be kept, dropped, or sanitized.

This means applications cannot reliably use resourceEventMapper as the single place to
sanitize auto-tracked XHR resource URLs before they are reported to Datadog.

What we would like to see

We would like resourceEventMapper to be applied to auto-tracked XHR resources before native
startResource is called.

The mapper should receive resource URL context, for example through
resourceContext.responseURL, so applications can inspect and rewrite the URL before it is
reported.

Expected behavior:

  • If resourceEventMapper rewrites resourceContext.responseURL, the sanitized URL is used
    for the reported RUM resource.
  • If resourceEventMapper returns null, the auto-tracked resource is dropped before native
    tracking starts.
  • Runtime calls to DdRum.registerResourceEventMapper and
    DdRum.unregisterResourceEventMapper update the mapper used by already-enabled automatic
    XHR tracking.
  • Existing resource tracking behavior, including tracing sample rate updates and internal SDK
    resource filters, continues to work.

This would let React Native apps prevent PII leaks in Datadog resource URLs while keeping
behavior consistent with frontend instrumentation.

Proposed solution

Here is the suggested implementation:

https://github.com/teplymax/dd-sdk-reactnative/tree/teplymax/apply-resourceEventMapper-to-auto-tracked-resources

Patch to test this out:
@datadog+mobile-react-native+3.5.1.patch

Other relevant information

No response

Dominant language
TypeScript
Stars
145
Forks
65
Avg merge
2d 18h
Merged PRs (30d)
19

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from DataDog/dd-sdk-reactnative

All issues in DataDog/dd-sdk-reactnative

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.